Live data from Hacker News

HTTPS on Your Landing Page Is Important

troyhunt.com

201–210 of 307 posts

Re: HTTPS on Your Landing Page Is Important

#201
post #24

Earlier quoted context omitted.

The important thing for all of us to remember, is that in any given conversation we may be idiot. Until I'm sure the other person doesn't know what they're talking about, I try and assume they're right.

> The important thing for all of us to remember, is that in any given conversation we may be idiot. Alternative take, particularly pertinent to this situation: The person handling twitter is not a technical person, but a customer support person who handles hundreds of dumb questions, day in, day out, from customers who have no clue what they're doing but will often throw technical terms around. Expecting solid techni…

Thank you, voice of reason.

Re: HTTPS on Your Landing Page Is Important

#202
Anyone want to hear a joke? Go to the financial ombudsman homepage [1]...

Bare in mind, on their complaints page you can download a complaints Word document, fully capable of having embedded VB script [2].

Also, it took them _months_ to sort out an issue where they would only check for 3 numbers (pin) and 3 letters (password), always asking for the first, second and third characters.

Also-also, I remember a while back not being able to access my card (for about a day) because a single engineer accidentally corrupted their main database.

[1] http://financial-ombudsman.org.uk

[2] http://financial-ombudsman.org.uk/consumer/complaints.htm

Re: HTTPS on Your Landing Page Is Important

#203
post #150

It's 2017, and my social media account is protected by a tamper-proof phish-resistant embedded-encryption U2F microcontroller dongle, in addition to a password of virtually unlimited length and charset. Meanwhile, my bank has a max password length of 12 and I can only use an alphabet of roughly 64 characters. The future is here folks. And it sucks.

My bank only recently upgraded max password length from 8 to 12. Oh, and no special characters please.

By "special character", do they mean punctuation? Or the null byte?

Re: HTTPS on Your Landing Page Is Important

#204

It's 2017, and my social media account is protected by a tamper-proof phish-resistant embedded-encryption U2F microcontroller dongle, in addition to a password of virtually unlimited length and charset. Meanwhile, my bank has a max password length of 12 and I can only use an alphabet of roughly 64 characters. The future is here folks. And it sucks.

> my bank has a max password length of 12 Look at Mr. PrivateBanking over there, my one is 5. Amount in words : Five. And that is after they updated all their software and moved to a new datacenter and everything recently. Granted I have a hardware dongle to authenticate any transactions , but to gain access to all my information, five characters is all the protection they wish to offer...

Why are you still with them?

Re: HTTPS on Your Landing Page Is Important

#205
post #32

I'm not really surprised, UK banks are absolutely terrible in terms of their product and even worse in supporting clients having valid points. Another example would be MetroBank that recently changed password prompt to a masked password prompt (in addition to already existing masked PIN alongside) ignoring the research proving its a horrible user experience and in fact lowers the security or (not a bank, but still ma…

When I was with Three they had a phone password which was not the same password as my online account password. I have nothing informed to say on the security of this approach, other than that asking customers for their online account password would be completely unacceptable in all circumstances, and shouldn't even be helpful because as we all know passwords should not be stored in a reversible format.

Re: HTTPS on Your Landing Page Is Important

#206

Earlier quoted context omitted.

Couldn't "private" also not mean "private"? For instance: when you're on Facebook, couldn't people think they are exchanging private messages because the address bar says "private"? "secure" means "secure connection" to me, and it sounds perfectly appropriate. Maybe you can't find a better term for "secure" because it's perfectly fine, already..?

> Maybe you can't find a better term for "secure" because it's perfectly fine, already..? Could be! Someone else suggested "Encrypted", seems like a good word. I really don't know.

If you're looking to be user-friendly, I'm not sure "encrypted" would work, because many people aren't going to know what it means.

I'm thinking specially in its inactive "not encrypted" version, where people aren't going to appreciate the gravity of a page being "not encrypted".

I bet the folks at Google already thought about this through.

Re: HTTPS on Your Landing Page Is Important

#207

A bit side topic: It seems that every time Troy interacts with a company on Twitter, they never seem to click on to who he is, until it's probably too late and they look like fools. It's just so amusing to see companies trying to condescend to Troy, when he's one of the most visible authorities on web security on the planet (not necessarily the most authoritative, but the most well known). I occasionally get this whe…

This being NatWest the penny probably still hasn’t dropped, and they’re probably trying to get him arrested for “hacking our internet”. I doubt they’ll actually implement a change. The general approach in the UK has been to not blame banks at all for poor security, and to punish anyone who finds a security issue severely.

NatWest are particularly terrible. Last time I checked, in-branch they were still using Internet Explorer to visit an http (not https) site on their intranet to launch via Java Web Start a thin client to log in to their (I assume) mainframe to actually do things.

There's a number of places in that chain of events that something could go nastily wrong, despite them owning every part of that chain.

Re: HTTPS on Your Landing Page Is Important

#208
post #207

Earlier quoted context omitted.

This being NatWest the penny probably still hasn’t dropped, and they’re probably trying to get him arrested for “hacking our internet”. I doubt they’ll actually implement a change. The general approach in the UK has been to not blame banks at all for poor security, and to punish anyone who finds a security issue severely.

NatWest are particularly terrible. Last time I checked, in-branch they were still using Internet Explorer to visit an http (not https) site on their intranet to launch via Java Web Start a thin client to log in to their (I assume) mainframe to actually do things. There's a number of places in that chain of events that something could go nastily wrong, despite them owning every part of that chain.

I was in branch the other week and they were doing exactly that... from Windows XP. Staff member told me they were upgrading to Windows 10 soon and they couldn’t wait.

Re: HTTPS on Your Landing Page Is Important

#209

Monzo [1], Starling [2], Atom [3] and Tandem [4] all manage to have HTTPS landing pages. If they can, there isn't any excuse for the more established banks not to as well. Hopefully their mobile apps use HTTPS for everything too? Apparently 35% of all UK banks have insecure landing pages. [5][6] [1] https://monzo.com [2] https://www.starlingbank.com [3] https://www.atombank.co.uk [4] https://www.tandem.co.uk [5] http…

> Hopefully their mobile apps use HTTPS for everything too?

Well, HSBC's didn't: https://threatpost.com/banking-apps-found-vulnerable-to-mitm...

Re: HTTPS on Your Landing Page Is Important

#210
post #68

Earlier quoted context omitted.

When I worked for Chase on their main app, the policy for support was the current version of the browser, minus one.

To be fair Chase seems (on the surface) to have the best site/app/whatever of the major US banks. The app is pretty great.

Chase doesn't like chromium. It'll randomly load a mobile page if your user agent string is chromium. Not to mention, none of the US banks allow standard 2FA (TOTP). If they have 2FA at all, it'll be SMS.
Post reply on HN